Lead Cyber Threat Analyst
- Hiring from
- Australia
- Work type
- Hybrid
- Posted
522,152 remote jobs, straight from company career pages
100% free · New jobs every hour
Show job descriptionHide job description
One of our Federal Government Clients is seeking to engage a Lead Cyber Threat Analyst- EL1
Please check below all the job details:
- Contract Duration: 03 Years (12 Months initially + 24 Months extension)
- Work Location: Canberra (Hybrid Working available)
- Work Arrangement: First 6 weeks work fulltime onsite, thereafter work 3 days from office and 2 days from home each week
- Eligibility: You must need to have NV1 Security Clearance or above
- Tentative Start Date: 23rd Nov 2026
- Working Hours: 8 hours a day/ 40 hours a week
Overview
Cyber Threat Analysts need to understand cyber intrusion activities then use their research skills to provide reporting on threat modelling and intelligence.
The Senior Cyber Threat Analyst with cyber threat hunting, malware analysis, AI engineering and incident response skillset and expertise who will be responsible for understanding cyber intrusion activities and applying technical analysis, research and investigative methods to identify, assess and report on malicious or suspicious activity affecting the agency. The role supports proactive threat hunting, incident response, and intelligence-informed analysis to strengthen the agency’s cyber defensive posture.
Key duties and responsibilities:
- Conduct proactive cyber hunt activities based on hypotheses, intelligence reporting, anomalous activity and identified risks.
- Investigate cyber intrusion activity and suspicious behaviour across networks, systems and data sources.
- Support incident response activities through technical triage, investigation, containment support and reporting.
- Research adversary tactics, techniques and procedures and translate findings into threat modelling and actionable reporting.
- Work closely with threat intelligence, detection, vulnerability management and other cyber teams to improve investigative outcomes and defensive uplift.
- Document investigative findings, methods, artefacts and recommendations in a clear and defensible manner.
- Contribute to knowledge transfer, mentoring and capability uplift of APS staff within the Hunt and Incident Response function.
- Ability to work across multiple cyber disciplines and contribute to technically complex operational outcomes.
- Manage intrusion and analysis work with the ability to make decisions on appropriate response and escalate as necessary.
- Manage complex threat intelligence/modelling tasks and/or threat assessments.
- Manage major Information Security incidents.
- Assist with corporate response to an Information Security incident.
- Identifies and implements improved controls to reflect changes in factors such as threat levels and legislation.
- Undertake advanced research into vulnerabilities or cryptography, including producing complex exploits, undertake effective reverse engineering and/or effectively researched mitigation bypasses.
- Analyse security risks, identify control deficiencies, develop remediation strategies and implement security engineering solutions within large and complex ICT environments.
Essential Technical Skills
- Microsoft Defender XDR: Advanced Hunting using KQL, investigation of endpoint, network and email events.
- Elastic / Kibana: Log analysis using KQL, Lucene or ES|QL.
- ExtraHop: Network traffic analysis and malicious IP/domain investigations.
- Linux: Log investigation, Windows event logs and firewall logs.
- Threat Intelligence: DNS investigations, threat indicators and adversary TTP analysis.
- Strong experience in SIEM/EDR, incident response, digital forensics and cyber threat hunting.
- Understanding of PSPF, ISM, Essential Eight and NIST.
Highly Desirable
- Microsoft Sentinel, QRadar, SOAR, Rapid7, Tenable.
- Malware analysis and reverse engineering tools (FlareVM, HxD, PEStudio, Sysinternals).
- Python/PowerShell scripting and security automation.
- Azure, AWS, GCP, Active Directory, Entra ID and IAM.
- Experience integrating security tools and developing automated detection/response playbooks.
- CREST certifications or relevant cyber security qualification
The Next step is easy: If you are interested, you may send an email to Krishna.R@italliance.com.au
Referral incentive program: As always, we have the candidate referral incentive program through which you will get $1000 for each successful referral after the successful selection and joining of the referred candidates